Memory hook: AWS secures the underlying cloud; you still control your identities, data and chosen configuration.
Must remember
- On EC2, AWS manages facilities, hardware and virtualisation; the customer patches the guest OS and manages application security. With RDS, AWS manages more database infrastructure and maintenance; customers still manage data, access and application use. With Lambda, AWS manages the underlying servers; customers own function code, dependency choices and permissions.
- Authentication establishes identity; authorisation decides permitted actions. An IAM policy states an effect, actions, resources and optional conditions. Explicit deny wins over an applicable allow. Default absence of permission means denial.
- Users are identities; groups organise permissions for users; roles provide temporary credentials when assumed. Roles have a trust policy controlling who may assume them and permissions controlling what they may do. A group is not a runtime service identity.
- Prefer workforce federation through IAM Identity Center and temporary roles for workloads. MFA adds another factor. A console password and programmatic access keys are different credentials; a password change does not rotate access keys.
- Protect the root user, avoid routine root use and do not create root access keys. Some account operations remain root-only or require specific centralised root capabilities; consult the current task list rather than granting root to every administrator.
- Apply least privilege, review unused access and remove unnecessary credentials. A credentials report summarises IAM-user credential status; access analysis helps discover risky or unused permissions.
- Secrets Manager stores secrets with rotation integration. Systems Manager Parameter Store stores configuration and SecureString values. Never embed long-lived keys in code, AMIs or public repositories.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Application on EC2 needs S3 access | Instance role with scoped permissions. |
| Employees already use a corporate identity provider | Federation and IAM Identity Center. |
| Database credentials need managed rotation | Secrets Manager with supported rotation configuration. |
Traps
- MFA does not expand permissions.
- An administrator policy is not the same identity as the root user.
- Managed services reduce operational work but do not decide which customers should access your data.
Active recall
1. Who patches the EC2 guest operating system?
The customer. AWS maintains the host infrastructure.
2. A developer needs cross-account access for one hour. Which credential pattern fits?
Assume a trusted role and use temporary credentials, rather than sharing a permanent user key.
3. An allow policy and an applicable explicit deny both match. What happens?
The request is denied.
4. Can an IAM group be attached to EC2 as its workload identity?
No. Use an IAM role through an instance profile.
5. Does encrypting a bucket repair an overly broad access policy?
No. Encryption and authorisation solve different problems.